Independent certification body · Registered in Republic of Estonia Standards Register Contact
European Digital
Certification Agency
Building trust in European technology

EDCA-P09 · Governed by EDCA-STD-10

Remote Identity Proofing Certification

An assessment of a service that establishes a person's identity without meeting them. It examines how identity evidence is captured and checked for authenticity, how the applicant is bound to that evidence, when a human reviews the decision, and what record survives to show why the decision was taken.

What this certification is not

This certification is an assessment of a service against the Agency's own standard. It is not qualification as a trust service provider under Regulation (EU) No 910/2014 as amended by Regulation (EU) 2024/1183, not a conformity assessment for the purposes of that Regulation, and not accreditation as a conformity assessment body. It confers no presumption of conformity with ETSI TS 119 461 or any other external standard, although the Agency's requirements draw on that body of work.

Scope of assessment

The scope is agreed in writing before the assessment begins and is printed on the certificate. A certificate says nothing outside its scope.

  • Named identity proofing services and the assurance they claim
  • Capture of identity evidence and its authenticity checks
  • Binding of the applicant to the evidence, including liveness where used
  • The automated decision and the human review path behind it
  • Retention of evidence and of decision records

What is examined

Each area below is assessed against the requirements of EDCA-STD-10, Remote Identity Proofing, version 1.0.

  • Authenticity checks applied to identity documents
  • Presentation attack detection and liveness
  • Binding of the person to the document
  • Quality of automated extraction and comparison
  • Human review: when it is triggered, by whom, against what criteria
  • Retention, integrity and retrievability of evidence
  • Measured error rates and how they are monitored over time
  • Treatment of biometric and other special category data

Programme particulars

Programme code
EDCA-P09
Governing standard
EDCA-STD-10 — Remote Identity Proofing, version 1.0, issued 28 July 2026
Levels available
Level II — EDCA Security Verified
Level III — EDCA Advanced Compliance
Level IV — EDCA Trusted Technology
Typical duration
Twelve to eighteen weeks from application to decision.
Surveillance
As required by the level held. See level requirements.

Evidence normally requested

The list is indicative. The evidence request issued after the preliminary assessment is specific to the agreed scope.

  1. Service description stating the level of assurance claimed
  2. Inventory of document authenticity checks by document type
  3. Presentation attack detection testing results
  4. Extraction and comparison accuracy measurements
  5. Human review procedure and reviewer competence records
  6. Retention schedule and a demonstration of retrieval
  7. Data protection impact assessment

Apply for Remote Identity Proofing Certification

Submitting an application costs nothing and commits you to nothing. The Agency will confirm eligibility, propose a scope and issue a fee schedule before any assessment work begins.